Business Associate Contract Provisions: A Checklist
HIPAA names nine things a business associate agreement has to do. Not nine paragraphs, not nine pages — nine obligations, spelled out at 45 CFR 164.504(e). Most of the signed BAAs sitting in your vendor folder cover six or seven of them well and gesture vaguely at the rest. The gaps are predictable, and they are the same gaps that turn a vendor's bad Tuesday into your breach notification.
This is a working checklist of the business associate contract provisions you are required to have, what each one should actually say, and what evidence proves the provision was live and not just laminated. If you sign vendor contracts, answer records requests, or own the vendor inventory, this is your list.
The Nine Business Associate Contract Provisions HIPAA Requires
Every BAA between your practice and a business associate must, at minimum, do the following:
- Describe the permitted and required uses and disclosures of PHI by the business associate — and they can be no broader than what you yourself could do.
- Prohibit any other use or disclosure except as permitted by the contract or required by law.
- Require appropriate safeguards, including compliance with the Security Rule for electronic PHI.
- Require reporting to you of any use or disclosure not permitted by the contract, any security incident, and any breach of unsecured PHI.
- Bind subcontractors to the same restrictions and conditions through a written agreement.
- Make PHI available so you can satisfy patient access under 164.524, amendment requests under 164.526, and accounting of disclosures under 164.528.
- Make internal practices, books, and records available to HHS for compliance review.
- Return or destroy all PHI at termination, if feasible, and extend the protections indefinitely if it is not.
- Authorize termination by you if the business associate materially violates the contract.
HHS publishes sample business associate agreement provisions that track this list clause by clause. Treat that page as the floor, not the ceiling — it is deliberately generic and leaves every operational deadline blank.
Where Business Associate Contract Provisions Usually Fall Short
The required elements are not hard to include. What separates a real BAA from a decorative one is whether the provisions contain numbers, names, and consequences.
Breach reporting with no clock
"Business Associate shall report to Covered Entity any breach of unsecured PHI without unreasonable delay." That sentence satisfies the regulation and protects nobody. You have 60 calendar days from discovery to notify affected individuals under the Breach Notification Rule, and a business associate's discovery is imputed to you when they act as your agent.
Write a hard internal deadline. Ten calendar days for a confirmed breach, five business days for a suspected security incident, 24 hours for ransomware or any event that takes their systems offline. Require the notice to include the elements you need for your own notification letters: date of the incident, date of discovery, individuals affected, data elements involved, and what they have done to mitigate.
Subcontractor language that stops at "may use"
Your billing company uses an offshore coding team. Your telehealth platform uses a cloud host. Your shredding vendor subcontracts transport. Each of those downstream entities is a business associate in its own right and needs its own BAA, executed by the vendor above them — not by you.
Ask for the list. A defensible clause says the business associate will maintain a current inventory of subcontractors with access to your PHI, provide it on request within ten business days, and notify you before adding a new one. Vendors who cannot produce that list within two weeks generally cannot produce it at all.
The return-or-destroy clause nobody executes
This is the provision most often written correctly and performed never. When you terminate a vendor, someone has to actually ask for the certificate of destruction or the confirmation that data was returned. Put a named role on it — practice manager, privacy officer, whoever closes out the contract — and put the deadline in the contract: 30 days from termination, written certification, signed.
Insurance, audit rights, and indemnification
None of these are HIPAA requirements. All of them are why you have leverage after an incident. Cyber liability coverage with a stated minimum, the right to request a copy of the vendor's most recent risk analysis, and indemnification for breach notification costs are contract terms, not regulatory terms. Negotiate them separately so a vendor cannot claim "our BAA is the HHS template" as a reason to refuse.
Timelines Worth Writing Into Every BAA
The regulation gives you deadlines for your own obligations and stays silent on how fast your vendors must move. Close that gap explicitly:
- Patient access requests routed through the vendor: 10 business days to produce records. You have 30 days total under 164.524; you cannot spend 25 of them waiting.
- Amendment requests: 15 business days for the vendor to make or note the amendment in their copy of the record.
- Accounting of disclosures: 15 business days to provide their log. Your patient-facing deadline is 60 days.
- Confirmed breach notice to you: 10 calendar days, with an initial notice in 24 hours for anything involving ransomware, unauthorized access to a database, or lost unencrypted media.
- Security incident report: 5 business days, with an exception for routine blocked scans and failed logins that you can define as reportable in aggregate quarterly.
- Return or destruction at termination: 30 days, written certification.
- Subcontractor list on request: 10 business days.
That last set of numbers is the difference between a BAA you can enforce and a BAA you can only file.
A Worked Example: The Transcription Vendor
A four-provider orthopedic group uses an overseas transcription service. The BAA was signed in 2019, drafted by the vendor, three pages. In November a patient's operative note surfaces in a search result because the vendor left a storage bucket open.
Walk the provisions. Permitted uses: the contract allows the vendor to use PHI for "business operations," which is broader than what the practice itself could authorize — a defect. Safeguards: the clause says the vendor will comply with "applicable law," not the Security Rule — a defect. Reporting: "prompt notice" with no clock, so the practice learns of the exposure 41 days after the vendor's own discovery, leaving 19 days to identify 2,300 affected patients, draft letters, and post substitute notice. Subcontractors: the vendor uses a separate storage provider that the practice never knew existed and has no BAA with the transcription company.
Nothing in this scenario is exotic. Every one of those defects is visible on a first read of the agreement, before any incident. That is the point of an annual BAA review — you find these while the stakes are still theoretical.
What the Documented Evidence Looks Like
An investigator asking about your business associate contract provisions is not asking whether you believe you have BAAs. They are asking for artifacts. Assemble these:
- A vendor inventory listing every entity that creates, receives, maintains, or transmits PHI on your behalf, with the service performed, the categories of PHI involved, BAA execution date, and renewal or review date.
- Fully executed agreements with signatures and dates from both parties. An unsigned draft in a shared drive is not satisfactory assurance.
- Amendment history showing when a BAA was updated and why — a new service line, a new subcontractor, a change in data flow.
- Subcontractor attestations or lists collected under the clause above.
- Termination files containing the certificate of destruction or return confirmation for every vendor you have offboarded.
- Evidence of the annual review — a dated log showing who read which BAA, what gaps they found, and what they did about it.
If your current agreements were drafted by whichever vendor happened to send one first, they are not consistent with each other and probably not consistent with your actual data flows. Rebuilding them from a standard set of clauses is faster than redlining nine different vendor templates — a step-by-step business associate agreement generator will walk you through the required provisions, let you set your own reporting deadlines, and export signature-ready PDF and DOCX versions you can send out the same afternoon.
Who Owns Each Piece Inside the Practice
Privacy officer
Owns the vendor inventory and the annual review. Signs off before any new vendor touches PHI. Maintains the termination file.
Practice manager or contracts lead
Cannot execute a services agreement with a PHI-touching vendor until the BAA is countersigned. Make that a hard gate in your procurement workflow, not a courtesy step.
IT or security lead
Reviews the safeguards and security incident provisions, and confirms the technical claims match reality — encryption at rest and in transit, access controls, audit logging. This is also where the Security Rule risk analysis and BAA review inform each other; NIST's SP 800-66r2 maps Security Rule requirements to concrete controls you can ask vendors about by name.
Front desk and clinical staff
Owns nothing here except the one rule that matters: no new software, no new app, no new service touching patient information without routing it to the privacy officer first. Shadow IT is where most missing BAAs come from.
Which Vendors Do Not Need a BAA
Over-papering wastes time and clutters your inventory. You do not need a BAA with:
- Conduits — the postal service, a commercial courier, an ISP moving encrypted traffic. Transmission only, random or infrequent access.
- Other covered entities receiving PHI for treatment — a referral to a specialist is a permitted treatment disclosure, not a business associate relationship.
- Health plans receiving PHI for payment.
- Your own workforce, including contractors who function as workforce members under your direct control.
- Vendors with no PHI access at all — the landscaper, the coffee service. A cleaning crew working in an area with open charts is a closer call; lock the charts.
HHS keeps useful guidance on who counts as a business associate, including the direct liability business associates carry for their own violations since the Omnibus Rule. That direct liability does not reduce yours — you still need the contract.
A 90-Day Cleanup Plan
Days 1–15. Build or refresh the vendor inventory. Pull it from accounts payable, not memory — every recurring payment gets a yes/no on PHI access.
Days 16–45. Locate the executed BAA for every yes. Any vendor without one goes on a remediation list with a named owner and a date.
Days 46–75. Score each existing BAA against the nine provisions plus your timeline table. Sort into pass, amend, and replace.
Days 76–90. Send amendments and new agreements. Document who received what and when. Calendar the next annual review before you close the project.
One more forward-looking note: HHS proposed significant Security Rule modifications in January 2025, including tighter expectations around business associate verification of technical safeguards. The proposal is not final as of today, so nothing in it changes your obligations right now — but drafting your BAAs with specific, verifiable safeguard language today means fewer amendments later.
If your gap list runs past BAAs into missing policies or an outdated risk analysis, the same problem usually has the same root: documentation that was assembled once and never maintained. Getting your HIPAA risk analysis and policy set generated and dated gives your annual BAA review something to reference. Start with the vendor inventory this week — it is the shortest path to knowing how big the problem actually is.